PT-2023-1972 · Apache+6 · Apache Openoffice+7
CVE-2022-38745
·
Publicado
2023-03-24
·
Atualizado
2025-02-13
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Apache OpenOffice versions before 4.1.14
Description
The issue is related to the possibility of adding an empty entry to the Java class path in Apache OpenOffice. This could allow a remote attacker to execute arbitrary Java code from the current directory by loading a specially crafted java file.
Recommendations
For versions before 4.1.14, update to version 4.1.14 or later to resolve the issue. As a temporary workaround, consider restricting access to the Java class path to minimize the risk of exploitation.
Exploit
Correção
Uncontrolled Search Path Element
Code Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Almalinux
Apache Openoffice
Astra Linux
Centos
Linuxmint
Openoffice
Red Hat
Ubuntu